network access during package build (was Re: Bug#759762: ITP: libz-mingw-w64 -- compression library (targeting Windows))

2014-09-02 Thread Thorsten Glaser
On Mon, 1 Sep 2014, Adam Borowski wrote: Also, should we detect all other attempts to contact the outside network, and swat such builds with extreme prejudice? Yes. These can be privacy breeches, licence violations (download things that change what gets embedded into the packages), and all

Re: network access during package build (was Re: Bug#759762: ITP: libz-mingw-w64 -- compression library (targeting Windows))

2014-09-02 Thread Adam Borowski
On Tue, Sep 02, 2014 at 01:28:13PM +0200, Thorsten Glaser wrote: On Mon, 1 Sep 2014, Adam Borowski wrote: Also, should we detect all other attempts to contact the outside network, and swat such builds with extreme prejudice? Yes. These can be privacy breeches, licence violations

Re: network access during package build

2014-09-02 Thread Thorsten Glaser
On Tue, 2 Sep 2014, Adam Borowski wrote: (I’m aware that there is still *too* much “disable the network” in pbuilder. Sorry for not having had the time to work on that. I’ll try to do so shortly.) Could you tell us what's this too much? #753944 Here's how I would do it: unshare --net